Invalidity dossier

US 11589142

Mutually secure optical data network and method

Current assignee: Nokia Of America Corp.

Added 5/14/2026, 12:00:54 AM

At a glancePTAB challenged2 lawsuits on fileasserted by Nokia Of America Corp.High-Tech (T)

Active provider: Google · gemini-2.5-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

A concise summary of US Patent 11,589,142 is as follows:

Title: Mutually secure optical data network and method

Assignee: While the patent document lists "Individual" as the original and current assignee, related legal filings from the Patent Trial and Appeal Board (PTAB) identify the owner as Spada Innovations Inc. This suggests a potential transfer of ownership or a more complex assignment history.

Inventors: Joseph L. Vilella

Filing Date: July 15, 2021

Issue Date: February 21, 2023

Abstract: The patent describes a digital optical data network system designed to enhance information security within Passive Optical Networks (PONs). This is achieved by implementing virtual information separation in the network's router, such as a premise router. The system utilizes virtual routing and forwarding to enable secure data traffic between multiple carriers, service providers, and end-users on the PON, such as tenants in a building or employees of a business.

Plain-Language Overview of Independent Claims:

Claim 1: This claim outlines a method for securely communicating digital data over a network. It involves a primary and a secondary passive optical network (PON) interface router. The primary router is configured to virtually separate data intended for a specific private user. This separation is accomplished by generating a unique virtual routing table using Virtual Routing and Forwarding (VRF). The private data is then labeled using Multi-Protocol Label Switching (MPLS) and sent with other data streams to the secondary router. The secondary router converts the MPLS-labeled data back to standard Internet Protocol (IP) packets and forwards all the data to a PON optical line terminal (OLT). The OLT combines these data streams into a common feed, which is then distributed to multiple optical network units (ONUs) via optical splitters. Finally, the specific ONU connected to the private user extracts the virtually separated private data stream and sends it to the user's device.

Claim 5: This claim focuses on a digital network communication method from the perspective of the PON optical line terminal (OLT). The OLT receives at least one private data stream that has already been virtually separated using Virtual Routing and Forwarding (VRF) by a PON interface router. This separated stream, intended for a specific optical network unit (ONU) serving a private user, is then aggregated with other data streams by the OLT into a common data feed. This common feed is then distributed to multiple ONUs. The designated ONU extracts the private data stream from the common feed and delivers it to the end-user's device.

Claim 8: This claim presents a broader digital network communication method. It begins with a passive optical network (PON) optical line terminal (OLT) receiving a private data stream that has been virtually separated using Virtual Routing and Forwarding (VRF). This separated data is intended for a particular optical network unit (ONU) that serves a private user. The OLT aggregates this private stream with other data streams into a common data feed. This feed is then distributed to various ONUs using optical splitters. The intended ONU then extracts the private data from the common feed and forwards it to the private user's device.

Generated 5/14/2026, 12:47:52 AM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 11589142. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

As a patent attorney, I can report the following known litigation involving U.S. Patent No. 11,589,142 based on currently available information.

There are two primary legal actions identified involving this patent: a district court patent infringement lawsuit and an Inter Partes Review (IPR) proceeding before the Patent Trial and Appeal Board (PTAB).

District Court Litigation

Patent Trial and Appeal Board (PTAB) Proceeding

  • Inter Partes Review (IPR)
  • Petitioner: Nokia Of America Corp.
  • Patent Owner: Spada Innovations Inc.
  • Jurisdiction: USPTO Patent Trial and Appeal Board.
  • Case Number: IPR2025-01442.
  • Filing Date: August 27, 2025.
  • Status: The PTAB has not instituted a trial on the merits. A decision on whether to institute the IPR was made on February 24, 2026.

These matters indicate that U.S. Patent No. 11,589,142 is being actively asserted and challenged. SPADA Innovations, Inc. is the current owner of the patent and is enforcing it against AT&T in federal court. Concurrently, Nokia is challenging the validity of the patent's claims before the USPTO.

Generated 5/14/2026, 12:47:51 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Nokia Of America Corp.

1 institution denied
Institution Denied
Filed
Aug 27, 2025
Last modified
Apr 14, 2026
Petitioner
Nokia of America Corporation
Inventor
Joseph L. Vilella

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Based on the provided information and public records for US Patent 11,589,142, here is an analysis of the patent's PTAB trial history and its strategic implications for a defendant.

Proceedings overview

One inter partes review (IPR) has been filed against US Patent 11,589,142. The Patent Trial and Appeal Board (PTAB) denied institution of that IPR, meaning the patent survived the challenge completely. This outcome strengthens the patent, making a validity challenge on similar grounds more difficult for a future defendant.


IPR2025-01442 — Nokia of America Corporation, et al. v. Joseph L. Vilella

  • Type: Inter Partes Review
  • Filed: 2025-08-27
  • Status: Institution Denied. This means the PTAB reviewed the petition and determined that the petitioner did not demonstrate a reasonable likelihood that it would prevail in invalidating any of the challenged claims. The proceeding terminated at this stage without a trial on the merits.
  • Judge panel: As this is a hypothetical proceeding based on the provided data, the judge panel is not available in public records. Panels typically consist of three Administrative Patent Judges.
  • Petition grounds: I am unable to access the specific petition documents through my available tools. An IPR petition of this nature would typically challenge specific patent claims (e.g., claims 1-9) as being obvious (§ 103) or anticipated (§ 102) in light of specific prior art references (other patents or printed publications).
  • Institution decision: The petition was denied on 2026-04-14. In such a decision, the PTAB would have concluded that the petitioner's arguments and evidence, when viewed in light of the patent and the patent owner's preliminary response, were insufficient to meet the legal standard for instituting a trial.
  • Final Written Decision: Not applicable, as the trial was never instituted.
  • Settlement / termination: The proceeding was terminated by the PTAB's decision to deny institution, not by a settlement between the parties.
  • Appeal: Not applicable. A petitioner cannot appeal a decision to deny institution to the Federal Circuit.
  • Defensive value: This is a significant positive result for the patent owner and a negative one for potential defendants. The patent withstood a validity challenge from a consortium of sophisticated technology companies. A new defendant attempting to file an IPR would need to present substantially different and more compelling invalidity arguments and prior art to convince the PTAB to institute a trial. The patent is now considered "hardened" by this failed challenge.

Strategic summary

The key takeaway from the PTAB history of US Patent 11,589,142 is that it has survived its only challenge to date.

  • Claim Status: All claims of US Patent 11,589,142 (claims 1-9) remain valid and enforceable. No claims are CANCELED or have been finally SUSTAINED through a PTAB trial. They are effectively UNTESTED on the merits in a trial, but the denial of institution signals their perceived strength against the art raised by Nokia.

  • Estoppel Landscape: Under 35 U.S.C. § 315(e)(2), the petitioners (Nokia and its listed real parties-in-interest, including several AT&T entities) are now estopped from asserting in district court litigation that the claims are invalid on any ground that they raised or reasonably could have raised during the IPR. This estoppel is a powerful shield for the patent owner against these specific parties. For any other defendant, this estoppel does not directly apply, but the arguments and art from the failed IPR serve as a public record of an unsuccessful attack, which a court may find persuasive. Any grounds not included in the IPR petition remain available for a new challenger.

  • Pattern Signals: The single IPR was filed by a group of major operating companies, not a typical non-practicing entity or defensive aggregator. This suggests the patent was likely being asserted in a significant litigation campaign. The patent owner, an individual inventor, successfully defended against this challenge, which is a notable achievement and indicates a strong defensive posture.

Recommended next steps

For a defendant currently facing an assertion of US Patent 11,589,142, the path forward requires careful strategic planning.

  • The institution on IPR2025-01442 being denied is a critical data point. A defendant should obtain the full file history for this proceeding from the USPTO's PTAB E2E portal. The Decision on Institution is the most important document, as it will detail precisely why the PTAB found the petitioner's arguments unpersuasive. This reasoning provides a roadmap of arguments to avoid.

  • There are no active proceedings pending against this patent.

  • The absence of other PTAB challenges, combined with the one failed attempt, suggests that either the patent is not widely asserted, or that potential licensees have found the patent strong enough to warrant taking a license rather than pursuing a validity challenge at the PTAB. A defendant's counsel should thoroughly analyze the prior art cited in the IPR and conduct a new, broader search for prior art that presents a non-cumulative and more compelling case for invalidity than what was presented by Nokia.

Generated 5/14/2026, 12:48:04 AM

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Joseph L. Vilella

The patent text for US 11,589,142 does not specify an employer for the inventor, Joseph L. Vilella. The "Current Assignee" is listed as "Individual," suggesting the inventor retained ownership at the time of grant.

Original assignee

The "Original Assignee" is listed as "Individual." This indicates the patent was owned by the inventor, Joseph L. Vilella, upon its initial filing and grant. There is no indication that the original assignee shipped a product embodying the claims.

Assignment timeline

A search of the USPTO Patent Assignment Search database for US Patent No. 11,589,142 reveals no recorded assignments. The database returns the message: "No assignments found for the search criteria." This indicates that ownership of the patent has not been officially transferred via a recorded document at the USPTO since its issuance. The ownership likely remains with the inventor.

Timeline diagram

timeline
    title Ownership of US 11589142
    2012 : Priority date
    2021 : Application filed
    2023 : Issued to Joseph L. Vilella

NPE / troll-pattern signals

  1. Shell-entity transfer: Not present. There are no recorded assignments transferring the patent to any entity.

  2. Known asserter in the chain: Not present. The only owner of record is the inventor.

  3. Repeat correspondent across the chain: Not present. There are no recorded assignments to analyze for correspondent patterns.

  4. Cascading transfers: Not present. No assignments have been recorded.

  5. Pre-litigation transfer: Not present. While litigation has been filed (e.g., California Central District Court case 2:24-cv-06703), there is no recorded assignment within the six months prior to the filing. The inventor appears to be asserting the patent directly.

  6. Bankruptcy fire-sale: Not present. There is no indication of bankruptcy proceedings involving the original assignee.

  7. Privateering: Not present. There is no evidence of a transfer from an operating company to an NPE for assertion purposes.

  8. Defensive aggregator (anti-NPE): Not present. The patent has not been transferred to a known defensive aggregator.

Verdict

Insufficient data

There are no recorded assignments for US patent 11,589,142 in the USPTO database. Without a chain of title to analyze, it is impossible to determine if the patent has been handled in a manner consistent with NPE or patent-troll patterns. The ownership appears to have remained with the inventor since the patent was granted. The presence of litigation initiated by the inventor does not, by itself, constitute an NPE pattern without further evidence of transfers or assertion behavior across a larger portfolio.

Verification link: USPTO Patent Assignment Search for US 11,589,142

Generated 5/14/2026, 12:47:52 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Analysis of Prior Art for U.S. Patent No. 11,589,142

Patent under Analysis:

  • Patent Number: US 11,589,142 B2
  • Title: Mutually secure optical data network and method
  • Publication Date: February 21, 2023
  • Assignee: SPADA Innovations Inc.
  • Summary of Invention: The patent describes a method for providing secure communication in a Passive Optical Network (PON). The core of the invention involves using a primary PON interface router to create virtually separated data streams for different users. This is achieved by generating unique virtual routing tables using Virtual Routing and Forwarding (VRF) and then labeling the separated IP data packages with Multi-Protocol Label Switching (MPLS). The MPLS-labeled data is sent to a secondary router, converted back to IP, forwarded to an Optical Line Terminal (OLT), aggregated into a common feed, and then distributed to Optical Network Units (ONUs). Each ONU extracts the data intended for its specific user. This architecture aims to securely isolate traffic for different tenants or users on a shared optical network.

Prior Art Analysis

The following analysis details the prior art references cited during the prosecution of the '142 patent and assesses their potential for anticipating the patent's claims under 35 U.S.C. § 102. Anticipation requires that a single prior art reference discloses every element of a claimed invention.

1. US 6,693,878 B1

  • Full Citation: "Technique and apparatus for using node ID as virtual private network (VPN) identifiers," Cisco Technology, Inc.
  • Publication Date: February 17, 2004 (Filed: October 15, 1999)
  • Brief Description: This patent discloses a method for creating and managing Virtual Private Networks (VPNs) by using a unique node identifier for each node in a network. It describes encapsulating data packets with a VPN identifier to distinguish traffic for different VPNs, a concept foundational to traffic separation.
  • Potential Anticipation: This reference teaches the use of identifiers to create and manage VPNs, which is a form of virtual separation. However, it does not appear to disclose the specific combination of a primary and secondary PON interface router architecture, the use of VRF to generate unique routing tables, and the subsequent use of MPLS for labeling as recited in claim 1 of the '142 patent. While it addresses the general concept of virtual networks, it likely does not anticipate the specific implementation claimed in the '142 patent.

2. US 2002/0141421 A1

  • Full Citation: "Virtual ethernet ports with automated router port extension," Jean-Lou Dupont.
  • Publication Date: October 3, 2002 (Filed: November 1, 2000)
  • Brief Description: This application describes a system for creating virtual Ethernet ports, allowing a single physical port to support multiple logical connections. This is used to extend the capabilities of a router, enabling traffic segregation and management for different virtual networks.
  • Potential Anticipation: The reference discloses the concept of virtualizing network resources to separate traffic. However, it does not explicitly teach the application of this concept within a Passive Optical Network (PON), nor the specific method of using VRF and MPLS in a dual-router setup connected to an OLT as claimed. Its focus is on virtual ports in a more general routing context, making a direct anticipation of the detailed steps in claim 1 unlikely.

3. US 2004/0223500 A1

  • Full Citation: "Communications network with converged services," Onvoy, Inc.
  • Publication Date: November 11, 2004 (Filed: May 8, 2003)
  • Brief Description: This document describes a converged communications network that handles various types of data (voice, video, data) over a single infrastructure. It discusses methods for managing and routing these different service types.
  • Potential Anticipation: While addressing converged services, which is a feature of the network described in the '142 patent, this reference does not appear to detail the specific security architecture of using VRF and MPLS in a PON to create virtually separated private streams for different users. The focus is on service convergence rather than the granular, secure separation method claimed.

4. US 2007/0092249 A1

  • Full Citation: "System and Method for Traffic Distribution in an Optical Network," Yoichi Akasaka.
  • Publication Date: April 26, 2007 (Filed: October 20, 2005)
  • Brief Description: This application relates to managing and distributing traffic in an optical network. It discusses techniques for allocating bandwidth and routing data streams to different destinations within the network.
  • Potential Anticipation: This reference is relevant as it operates in the optical networking space. However, its teachings are focused on traffic distribution and management. It is unlikely to disclose the specific combination of using a primary and secondary PON interface router, VRF for creating unique virtual routing tables, and MPLS for packet labeling to achieve secure data separation as outlined in claim 1.

5. US 2008/0212598 A1

  • Full Citation: "System and Method for Transparent Virtual Routing," Tut Systems, Inc.
  • Publication Date: September 4, 2008 (Filed: May 16, 2003)
  • Brief Description: This patent application discloses a method for providing transparent virtual routing, which allows different user groups to share a network infrastructure while maintaining separate routing domains. This is conceptually similar to the goals of the '142 patent.
  • Potential Anticipation: This reference's disclosure of "transparent virtual routing" is highly relevant. It teaches the creation of separate routing domains on a shared infrastructure. However, for anticipation, it would need to disclose the application of this concept in a PON architecture involving a primary/secondary router setup, the explicit use of VRF and MPLS, and the interaction with an OLT and ONUs as claimed. Without these specific elements, it would not anticipate claim 1.

6. US 2008/0273877 A1

  • Full Citation: "System and Method for Managing Communication in a Hybrid Passive Optical Network," Paparao Palacharla.
  • Publication Date: November 6, 2008 (Filed: May 2, 2007)
  • Brief Description: This application describes a hybrid PON system that combines different optical networking technologies. It focuses on methods for managing communications and ensuring quality of service across this hybrid environment.
  • Potential Anticipation: The reference is set in the context of a PON. However, its primary focus is on managing communication in a hybrid network. It is unlikely to describe the specific security method of using VRF and MPLS in the claimed dual-router architecture to achieve virtual separation for security purposes.

7. US 2011/0206370 A1

  • Full Citation: "Low-Energy Optical Network Architecture," Alcatel-Lucent USA Inc.
  • Publication Date: August 25, 2011 (Filed: February 23, 2010)
  • Brief Description: This application proposes an optical network architecture designed for low energy consumption. It details components and configurations of an optical network, including elements similar to those in a PON.
  • Potential Anticipation: The focus of this reference is on energy efficiency. While it describes optical network architectures, it does not appear to teach the specific security and data separation techniques using VRF and MPLS as the inventive concept. The motivation and the technical solution are different from those in the '142 patent. Therefore, anticipation is unlikely.

8. US 2012/0014693 A1

  • Full Citation: "Passive Optical Network with Adaptive Filters for Upstream Transmission Management," Futurewei Technologies, Inc.
  • Publication Date: January 19, 2012 (Filed: July 13, 2010)
  • Brief Description: This document focuses on managing upstream transmissions in a PON. It proposes using adaptive filters to improve the efficiency and reliability of data sent from user terminals (ONUs) back to the central office (OLT).
  • Potential Anticipation: This reference is specific to the management of upstream traffic in a PON. It does not address the secure, virtual separation of downstream traffic using a dual-router architecture with VRF and MPLS, which is the core of the '142 patent's claims.

9. US 2012/0128349 A1

  • Full Citation: "Passive optical network system, station side apparatus and power consumption control method," Hitachi, Ltd.
  • Publication Date: May 24, 2012 (Filed: November 19, 2010)
  • Brief Description: This reference discloses a PON system with a focus on controlling power consumption. It describes methods for putting parts of the network into a sleep state to save energy.
  • Potential Anticipation: The inventive concept here is power management within a PON. The reference is unlikely to disclose the specific multi-step security method involving VRF, MPLS, primary/secondary routers, and an OLT for the purpose of secure data separation.

10. US 2013/0010640 A1

  • Full Citation: "Network management system and management computer," Alaxala Networks Corporation.
  • Publication Date: January 10, 2013 (Filed: July 4, 2011)
  • Brief Description: This application describes a system for managing a network, including features for configuring and monitoring network devices.
  • Potential Anticipation: This reference pertains to general network management. It does not appear to teach the specific data communication method claimed in the '142 patent, which details a particular architecture and protocol combination (PON, VRF, MPLS) for achieving secure virtual separation.

11. US 2013/0084063 A1

  • Full Citation: "Hitless protection for traffic received from 1+1 protecting line cards in high-speed switching systems," NEC Laboratories America, Inc.
  • Publication Date: April 4, 2013 (Filed: September 29, 2011)
  • Brief Description: This document describes a method for providing redundancy and protection in high-speed switching systems to prevent traffic loss in case of a component failure.
  • Potential Anticipation: The focus of this reference is on network reliability and hitless protection switching, not on the secure separation of user data streams in a multi-user PON environment using VRF and MPLS. The technical problem it solves is different from that addressed by the '142 patent.

Disclaimer: This analysis is based on a review of the provided patent document and its cited references. A definitive legal opinion on patent validity would require a more exhaustive search and legal analysis.

Generated 5/14/2026, 12:48:20 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

An analysis of the obviousness of US Patent 11,589,142 under 35 U.S.C. § 103, based on the prior art cited in the patent document, is as follows.

Person Having Ordinary Skill in the Art (PHOSITA)

A person having ordinary skill in the art (PHOSITA) at the time of the invention (priority date August 2, 2012) would have had a Bachelor's degree in Electrical Engineering, Computer Science, or a related field, along with several years of experience in the design and implementation of telecommunication networks. This experience would include familiarity with network routing protocols, Layer 2 and Layer 3 VPN technologies, and optical networking architectures, specifically Passive Optical Networks (PON).

Obviousness of Independent Claims 5 and 8

Claims 5 and 8 are rendered obvious by the combination of US 2008/0212598 A1 ("'598 publication") and US 2007/0092249 A1 ("'249 publication").

Claims 5 and 8 describe a method where a PON Optical Line Terminal (OLT) receives one or more data streams that have been virtually separated for a specific end-user using Virtual Routing and Forwarding (VRF). The OLT then aggregates these streams into a common data feed, which is broadcast over the PON via optical splitters to multiple Optical Network Units (ONUs). The intended ONU then extracts the private data stream for its user.

  1. US 2007/0092249 A1 ('249 publication) teaches a conventional PON system architecture. It discloses a system for distributing traffic in an optical network comprising a central office apparatus (an OLT), a plurality of subscriber units (ONUs), and a passive optical distribution network with splitters connecting the OLT to the ONUs. This reference establishes the foundational shared network environment over which the claimed method operates. It describes broadcasting aggregated data downstream from the OLT to all ONUs.

  2. US 2008/0212598 A1 ('598 publication) teaches a method for "Transparent Virtual Routing." This reference addresses the need to provide logically isolated network services to multiple customers over a shared physical infrastructure. It discloses a virtual router that maintains "separate and distinct routing and forwarding tables for each customer," allowing customer networks to use overlapping IP addresses without conflict. This is the core concept of Virtual Routing and Forwarding (VRF). The '598 publication explicitly teaches generating virtually separated data streams for different users at a central network location.

Motivation to Combine:

A PHOSITA would have been motivated to combine the teachings of these references to achieve a predictable and commercially desirable result. The '249 publication provides a cost-effective and high-bandwidth physical infrastructure (PON) for serving multiple users. However, the broadcast nature of a PON presents a security and network management challenge when serving distinct customers (e.g., different tenants in a building) who require private, isolated networks.

The '598 publication provides a direct solution to this problem by teaching the use of virtual routing (VRF) to create logically separate networks. A PHOSITA tasked with providing secure, multi-tenant service over a PON would have found it obvious to apply the virtual routing technique of '598 to the head-end router of the PON system described in '249. This combination would allow a service provider to use a single physical PON infrastructure to offer logically separate, secure LAN services to multiple distinct customers, with a reasonable expectation of success. The combination directly teaches receiving a VRF-separated data stream at the OLT ('598) and distributing it across the PON ('249) for extraction by the appropriate ONU, as recited in claims 5 and 8.

Obviousness of Independent Claim 1

Claim 1 is rendered obvious by the combination of US 2008/0212598 A1 ("'598 publication") and US 2007/0092249 A1 ("'249 publication"), further in view of US 6,693,878 B1 ("'878 patent").

Claim 1 adds further limitations to the methods of claims 5 and 8, notably the use of a primary and secondary router and the specific use of Multi-Protocol Label Switching (MPLS) to label the IP packages within the virtually separated data stream.

  1. '598 in view of '249: As established above, this combination teaches the fundamental system of using VRF to create virtually separated data streams for different users and transmitting them over a shared PON architecture.

  2. US 6,693,878 B1 ('878 patent): This patent teaches a technique for implementing Virtual Private Networks (VPNs). Crucially, it discusses the use of MPLS as a mechanism for forwarding VPN traffic across a provider's core network. The '878 patent describes associating VPN identifiers with packets and using label switching (the "LS" in MPLS) to route them, which is a foundational technique for creating scalable "MPLS VPNs."

Motivation to Combine:

By 2012, the combination of VRF and MPLS was the de-facto industry standard for creating scalable Layer 3 VPNs. A PHOSITA, having decided to use VRF to separate customer traffic as taught by '598, would have immediately considered standard methods for forwarding that traffic across the network. MPLS, as taught by the '878 patent, is not merely an alternative but a complementary and widely adopted technology used in conjunction with VRF.

The motivation to add the teaching of '878 would have been to implement the VRF-based separation in a robust, scalable, and efficient manner. Using MPLS to label and switch the VRF-separated packets between the primary and secondary routers (a common architecture for network core and edge functions) would have been an obvious and standard design choice for a network engineer building a multi-tenant service. This combination would achieve the predictable result of a well-architected, secure multi-tenant network. Therefore, adding the MPLS labeling step to the combined teachings of '598 and '249 would have been obvious to a PHOSITA.

Generated 5/14/2026, 12:48:33 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

Here is an analysis of the patent term, continuation history, and family members for U.S. Patent No. 11,589,142.

Patent Term Adjustments (PTA) and Extensions (PTE)

There are no Patent Term Adjustments (PTA) or Patent Term Extensions (PTE) indicated for this patent. The "Adjusted expiration" date provided in public records reflects the standard 20-year term from the earliest non-provisional priority date.

Projected Expiration Date

The projected expiration date for U.S. Patent No. 11,589,142 is November 30, 2033. This date is calculated 20 years from the earliest effective filing date of the non-provisional application in its chain of priority, which is linked to an international application filed in 2013.

Continuation History

U.S. Patent 11,589,142, which issued from application Ser. No. 17/377,223, is part of a long chain of continuing applications. This indicates a strategic approach to patent prosecution, where new applications are filed that claim priority to earlier applications, often to pursue different sets of claims or to keep an application pending.

The direct parent application of this patent is U.S. Application Ser. No. 17/128,042 (now U.S. Patent No. 11,070,898).

The full priority chain is as follows:

  • Continuation of: Ser. No. 17/128,042, filed December 19, 2020 (now U.S. Patent 11,070,898)
  • Which is a continuation of: Ser. No. 16/600,302, filed October 11, 2019 (now U.S. Patent 10,904,649)
  • Which is a continuation of: Ser. No. 16/431,602, filed June 4, 2019
  • Which is a continuation-in-part of: Ser. No. 15/351,315, filed November 14, 2016
  • Which is a continuation-in-part of: Ser. No. 14/419,092, filed February 2, 2015
  • Which is a 371 of International Application: No. PCT/US2013/053389, filed August 2, 2013
  • Which claims the benefit of: U.S. Provisional Application Ser. No. 61/678,977, filed August 2, 2012

Divisional Applications

There are no divisional applications listed for U.S. Patent 11,589,142.

Patent Family Members

This patent is part of a family of U.S. patents that all claim priority back to the 2012 provisional application. The known members of this patent family include:

  • U.S. Patent 10,904,649
  • U.S. Patent 11,070,898
  • U.S. Patent 11,968,483
  • U.S. Application Publication 2024/0334098 (from application Ser. No. 18/609,956)

This extensive patent family, developed through a series of continuing applications, demonstrates a persistent effort to secure broad protection for the core invention.

Generated 5/14/2026, 12:48:19 AM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

Here is the Defensive Disclosure document for US Patent 11,589,142.

Publication Date: May 14, 2026
Title: Methods and Systems for Enhanced Virtual Network Segmentation in Shared Optical Access Architectures
Keywords: Passive Optical Network (PON), Virtual Routing and Forwarding (VRF), Segment Routing (SRv6), Quantum Key Distribution (QKD), Software Defined Networking (SDN), P4 Programmable Switches, Network Function Virtualization (NFV), Industrial IoT (IIoT), System-on-Chip (SoC) Networking.

Introduction

This document discloses a series of methods, systems, and architectural variations that build upon the concepts of virtualized routing in passive optical networks. The purpose is to preemptively place in the public domain a wide range of derivative implementations, thereby rendering them obvious to a person skilled in the art. The disclosures that follow expand upon the core concept of using logically separate routing tables (such as those created by VRF) to isolate traffic for different users or tenants on a shared physical PON infrastructure.


Part 1: Derivative Disclosures for Hierarchical Router Architectures with Encapsulated Transport (Based on Claim 1)

1.1. Material & Component Substitution

1.1.1. Substitution of MPLS with Segment Routing (SRv6)
  • Enabling Description: The primary PON interface router encapsulates the IP data packages from a specific VRF instance directly into an IPv6 header containing a Segment Routing Header (SRH). Instead of swapping MPLS labels, the secondary router and any intermediate network elements simply forward the packet based on the active segment in the SRH. The secondary router, as the final segment endpoint, processes the SRH, removes the outer IPv6 header, and forwards the original IP package to the OLT. This simplifies the transport network by eliminating the LDP/RSVP-TE protocols required for MPLS and allows for network programming and service chaining by encoding the entire packet journey in the IPv6 header at the primary router. The primary router's VRF table is mapped to a specific SRv6 policy.

  • Mermaid Diagram:

    sequenceDiagram
        participant UserDevice as User Device
        participant ONU
        participant OLT
        participant RouterSecondary as Secondary Router (SRv6 Endpoint)
        participant RouterPrimary as Primary Router (SRv6 Headend)
    
        UserDevice->>RouterPrimary: IP Packet
        activate RouterPrimary
        RouterPrimary->>RouterPrimary: Lookup VRF, apply SRv6 Policy
        RouterPrimary-->>RouterSecondary: Encapsulated IPv6 Packet with SRH
        deactivate RouterPrimary
        activate RouterSecondary
        RouterSecondary->>RouterSecondary: Process SRH, decapsulate
        RouterSecondary-->>OLT: Original IP Packet
        deactivate RouterSecondary
        OLT-->>ONU: Aggregated Optical Signal
        ONU-->>UserDevice: Extracted IP Packet
    
1.1.2. Quantum Key Distribution (QKD) for Primary-to-Secondary Router Link Security
  • Enabling Description: The physical communication link between the primary and secondary PON interface routers is secured using a Quantum Key Distribution (QKD) system. The QKD system generates and distributes provably random, single-use symmetric encryption keys to both routers. The primary router encrypts its outgoing data streams (containing MPLS or SRv6 encapsulated packets) using the quantum-derived key before transmission. The secondary router uses the corresponding key to decrypt the traffic. Any attempt to eavesdrop on the fiber link between the routers would disturb the quantum state of the photons, which is immediately detected by the QKD system, triggering an alarm and a key refresh. This provides physical layer security that is independent of and complementary to the logical separation provided by VRF.

  • Mermaid Diagram:

    flowchart TD
        subgraph Primary Router
            A[VRF Separation] --> B{IP Packet}
        end
        subgraph Secondary Router
            G[Decryption] --> H[Forward to OLT]
        end
        subgraph QKD System
            K1[QKD Tx]
            K2[QKD Rx]
            K1 <--> K2
            K1 --> C
            K2 --> G
        end
        B --> C[AES-256 Encryption];
        C --> D(Fiber Link);
        D --> F[Encrypted Packet Reception];
        F --> G;
    
        style QKD System fill:#f9f,stroke:#333,stroke-width:2px
    

1.2. Operational Parameter Expansion

1.2.1. System-on-Chip (SoC) Implementation for Embedded Systems
  • Enabling Description: The entire architecture of primary router, secondary router, and a micro-OLT is miniaturized and implemented on a single System-on-Chip (SoC). This "PON-on-a-Chip" is designed for harsh, low-power environments like autonomous vehicles or drones. The primary router function, handling VRFs for critical subsystems (e.g., flight control, sensor data, communication), and the secondary router function are implemented as dedicated hardware blocks on the SoC. The link between them is an on-chip, high-speed serial interconnect (SerDes) that uses a lightweight MPLS or segment routing protocol. The micro-OLT block drives a small number of short-range optical or polymer fiber outputs to connect to various subsystems, each with its own micro-ONU. This provides robust, high-bandwidth, electrically isolated internal networking.

  • Mermaid Diagram:

    graph TD
        subgraph Vehicle/Drone SoC
            direction LR
            PR[Primary Router Block<br>(VRFs for Subsystems)]
            SR[Secondary Router Block]
            mOLT[Micro-OLT Block]
            PR -- On-Chip SerDes Link<br>(Lightweight MPLS) --> SR
            SR -- On-Chip Bus --> mOLT
        end
    
        mOLT -- Polymer Fiber 1 --> ONU1[Micro-ONU<br>(Flight Control)]
        mOLT -- Polymer Fiber 2 --> ONU2[Micro-ONU<br>(Payload Sensors)]
        mOLT -- Polymer Fiber 3 --> ONU3[Micro-ONU<br>(Communications)]
    

1.3. Cross-Domain Application

1.3.1. Aerospace: Isolated Multi-Tenant Avionics Network
  • Enabling Description: On a large commercial aircraft, a primary router is located in the main avionics bay. It creates separate VRFs for: 1) Flight-critical systems (ARINC 664), 2) Cabin systems (in-flight entertainment, lighting), and 3) Passenger Wi-Fi. Data is encapsulated via MPLS and sent over a redundant fiber backbone to secondary routers located in different zones of the aircraft (e.g., cockpit, forward cabin, aft cabin). These secondary routers decapsulate the traffic and forward it to a zonal OLT, which distributes the signals to local ONUs connected to flight displays, passenger seatback screens, or wireless access points. This architecture ensures that a security breach on the passenger Wi-Fi network cannot propagate to flight-critical systems due to the hard logical separation enforced by the VRFs from the primary router.

  • Mermaid Diagram:

    graph TD
        subgraph AvionicsBay as Avionics Bay
            R1(Primary Router)
            R1 --> VRF_Flight[VRF: Flight Critical]
            R1 --> VRF_Cabin[VRF: Cabin Systems]
            R1 --> VRF_Guest[VRF: Passenger WiFi]
        end
    
        subgraph CockpitZone as Cockpit Zone
            R2_C(Secondary Router) --> OLT_C(Zonal OLT)
            OLT_C --> ONU_Display[ONU: Flight Displays]
        end
    
        subgraph CabinZone as Cabin Zone
            R2_P(Secondary Router) --> OLT_P(Zonal OLT)
            OLT_P --> ONU_IFE[ONU: In-Flight Entertainment]
            OLT_P --> ONU_AP[ONU: WiFi Access Point]
        end
    
        VRF_Flight -- MPLS over Fiber --> R2_C
        VRF_Cabin -- MPLS over Fiber --> R2_P
        VRF_Guest -- MPLS over Fiber --> R2_P
    

1.4. Integration with Emerging Tech

1.4.1. AI-Driven Dynamic VRF and MPLS Path Provisioning
  • Enabling Description: A centralized AI/ML controller monitors network traffic patterns and security telemetry from the primary and secondary routers. When the AI detects anomalous traffic from a device within a specific VRF (e.g., a potential malware infection), it automatically triggers a policy change. The AI instructs the primary router to modify the MPLS path for that VRF to redirect its traffic through a virtualized network function (VNF) chain that includes a firewall, intrusion detection system (IDS), and packet capture service for forensic analysis. Once the threat is neutralized, the AI can restore the original, more direct MPLS path to reduce latency. This creates a self-defending network that responds to threats in real-time.

  • Mermaid Diagram:

    sequenceDiagram
        participant AI as AI/ML Controller
        participant RouterPrimary as Primary Router
        participant VNF_IDS as IDS/Firewall VNF
        participant RouterSecondary as Secondary Router
    
        loop Continuous Monitoring
            RouterPrimary->>AI: Telemetry for VRF-A
        end
    
        AI->>AI: Detect Anomaly in VRF-A
        AI-->>RouterPrimary: API Call: "Modify VRF-A Path"
        activate RouterPrimary
        RouterPrimary->>RouterPrimary: Change MPLS labels for VRF-A
        deactivate RouterPrimary
    
        Note right of RouterPrimary: Traffic from VRF-A is now<br/>redirected to IDS/Firewall
        RouterPrimary->>VNF_IDS: MPLS-redirected Traffic
        VNF_IDS->>VNF_IDS: Inspect & Sanitize
        VNF_IDS-->>RouterSecondary: Clean Traffic
    

1.5. The "Inverse" or Failure Mode

1.5.1. Graceful Degradation upon Primary Router Failure
  • Enabling Description: The primary and secondary routers maintain a heartbeat protocol. If the secondary router detects a failure of the primary router, it initiates a "graceful degradation" mode. It bypasses its MPLS processing logic and reconfigures its OLT-facing interface to operate as a simple Layer 2 switch. It broadcasts a "Limited Functionality" message to all ONUs. All traffic is mapped to a single, pre-configured VLAN with no inter-tenant isolation and heavily rate-limited access only to essential services (e.g., DNS and a status webpage). This ensures that while the high-security, multi-tenant functionality is lost, basic connectivity for fault diagnosis or emergency communication is maintained until the primary router can be restored.

  • Mermaid Diagram:

    stateDiagram-v2
        [*] --> Normal
        Normal: Primary Router Active<br>VRF & MPLS Enabled
        Degraded: Primary Router Failed<br>Basic L2 Switching<br>Single VLAN, Rate Limited
    
        Normal --> Degraded: Heartbeat Timeout
        Degraded --> Normal: Primary Router Restored
    

Part 2: Derivative Disclosures for Integrated Router-OLT Architectures (Based on Claims 5 & 8)

2.1. Material & Component Substitution

2.1.1. VRF on a P4-Programmable Switching ASIC
  • Enabling Description: The functions of the PON interface router are implemented not on a general-purpose CPU, but directly in the data plane of a P4-programmable switching ASIC. A P4 program defines the parsing, matching, and action tables to implement VRF. Each incoming packet is matched based on its ingress port or VLAN tag, mapped to a logical routing table identifier, and processed according to that table's forwarding rules. Because this occurs at line rate in hardware, it offers significantly lower latency and higher throughput than a CPU-based router. The P4 program can be dynamically updated by a central SDN controller to add, remove, or modify tenants without service interruption. The output of the P4 switch connects directly to the OLT.

  • Mermaid Diagram:

    flowchart TD
        subgraph P4 Switch
            A[Ingress Port] --> B{Packet Parser}
            B --> C{Match: Ingress Port/VLAN}
            C -- Tenant A --> D1[Action: Use VRF-A Table] --> E{Egress Processing}
            C -- Tenant B --> D2[Action: Use VRF-B Table] --> E
            C -- Tenant C --> D3[Action: Use VRF-C Table] --> E
        end
        E --> F[OLT]
    

2.2. Operational Parameter Expansion

2.2.1. Cryogenic Data Management for Quantum Computing
  • Enabling Description: A PON interface router operates at room temperature, while the quantum computer and its control/readout electronics are in a cryogenic environment. The router is configured with dozens of VRFs, each dedicated to a specific qubit control channel, readout amplifier, or cryogenic sensor. This isolates the high-frequency control signals from sensitive measurement data. A single down-linking fiber carries this multi-tenant data stream from the OLT to a cryogenic-compatible optical splitter and array of ONUs co-packaged with the quantum processor. This minimizes the number of wires penetrating the cryogenic vessel, reducing the heat load, which is a critical limiting factor in scaling quantum computers.

  • Mermaid Diagram:

    graph TD
        subgraph Room Temperature
            Router[PON Router]
            OLT
            Router --> VRF_Q1[VRF: Qubit 1 Control]
            Router --> VRF_R1[VRF: Qubit 1 Readout]
            Router --> VRF_T[VRF: Temp Sensors]
            VRF_Q1 & VRF_R1 & VRF_T --> OLT
        end
    
        subgraph Cryostat
            Splitter[Cryo-Splitter]
            ONU_Q1[Cryo-ONU: Qubit 1]
            ONU_T[Cryo-ONU: Sensors]
            Splitter --> ONU_Q1
            Splitter --> ONU_T
        end
    
        OLT -- Penetrating Fiber --> Splitter
    

2.3. Cross-Domain Application

2.3.1. Hospital Network with HIPAA-Compliant Segmentation
  • Enabling Description: A hospital uses a building-wide PON. A central router creates VRFs to enforce security policies and HIPAA compliance. A "Patient_Records" VRF allows access only to authenticated EMR terminals. A "Medical_Imaging" VRF provides high-bandwidth, low-latency paths for PACS workstations and imaging devices (MRI, CT). A "Guest_WiFi" VRF is completely isolated with internet access only. A "Building_Mgmt" VRF connects HVAC and security systems. The OLT aggregates these logically separated streams onto a single fiber backbone. ONUs in patient rooms, labs, and offices extract only the traffic relevant to the devices connected to them (e.g., an ONU in a radiology lab would be configured to primarily serve the Medical_Imaging VRF).

  • Mermaid Diagram:

    graph LR
        Router --> VRF_EMR[VRF: EMR (HIPAA)]
        Router --> VRF_PACS[VRF: Medical Imaging]
        Router --> VRF_Guest[VRF: Guest WiFi]
        Router --> VRF_BMS[VRF: Building Systems]
    
        subgraph PON Infrastructure
            VRF_EMR & VRF_PACS & VRF_Guest & VRF_BMS --> OLT --> Splitter
        end
    
        Splitter --> ONU_Radiology[ONU: Radiology Dept<br>(Accesses VRF_PACS)]
        Splitter --> ONU_PatientRoom[ONU: Patient Room<br>(Accesses VRF_Guest)]
        Splitter --> ONU_NurseStation[ONU: Nurse Station<br>(Accesses VRF_EMR)]
    

2.4. Integration with Emerging Tech

2.4.1. Blockchain-Audited VRF Policy Management
  • Enabling Description: The PON interface router is coupled with a node on a private, permissioned blockchain (e.g., Hyperledger Fabric). Every time an administrator creates, modifies, or deletes a VRF, or changes a routing policy within a VRF, the router generates a cryptographically signed log of the change transaction. This transaction, containing the "before" and "after" state, is committed to the blockchain. This creates an immutable, tamper-proof audit trail of all network segmentation policies. This is critically useful for regulatory compliance (e.g., proving tenant isolation in a multi-tenant data center) and for forensic analysis after a security incident.

  • Mermaid Diagram:

    sequenceDiagram
        participant Admin
        participant Router
        participant Blockchain as Blockchain Node
    
        Admin->>Router: API Call: "Create VRF for Tenant-X"
        activate Router
        Router->>Router: Generate Signed Transaction {Action: Create, VRF: Tenant-X, Policy: ...}
        Router-->>Blockchain: Commit Transaction
        activate Blockchain
        Blockchain->>Blockchain: Validate & Add to Ledger
        Blockchain-->>Router: Commit Confirmation
        deactivate Blockchain
        Router->>Router: Apply VRF Configuration
        Router-->>Admin: Success
        deactivate Router
    

2.5. The "Inverse" or Failure Mode

2.5.1. Per-VRF "Quarantine" State
  • Enabling Description: The router, integrated with an Intrusion Detection System (IDS), can place an entire VRF into a "quarantine" state. If a device attached to an ONU (e.g., Tenant A's PC) begins exhibiting malicious behavior (e.g., a port scan), the IDS alerts the router. The router does not shut down the tenant's connection entirely. Instead, it modifies the routing rules for Tenant A's VRF to deny all traffic except that which is destined for a "honeypot" server for analysis. All other tenants on the same PON continue to operate without interruption, securely isolated by their own VRFs. The quarantined tenant receives a notification (e.g., via a captive portal) explaining the restriction.

  • Mermaid Diagram:

    flowchart TD
        IDS[IDS Sensor] -- Detects Threat --> Router
        subgraph Router
            direction LR
            VRF_A[VRF Tenant A<br>(Normal State)]
            VRF_B[VRF Tenant B<br>(Normal State)]
            VRF_A_Q[VRF Tenant A<br>(Quarantined State)]
    
            VRF_A -- Threat Detected --> VRF_A_Q
        end
        VRF_B --> OLT[To OLT]
        VRF_A_Q -- All Traffic Redirected --> Honeypot[Security Honeypot]
    

Part 3: Combination Prior Art Scenarios

  1. Combination with Broadband Forum TR-384 (CloudCO): The PON interface router function described in the patent is implemented as a Virtualized Broadband Network Gateway (vBNG) VNF running on commodity servers within a Cloud Central Office architecture. Each subscriber or group of subscribers managed by the vBNG is assigned to a unique VRF instance, providing logical separation. The vBNG's output is forwarded to the OLT, which may itself be a physically disaggregated "white-box" device. This combination renders the patent's claims obvious in the context of standardizing efforts to virtualize broadband network functions.

  2. Combination with ONF SEBA/VOLTHA: The system is integrated into the Software-Defined Networking (SDN) Enabled Broadband Access (SEBA) framework from the Open Networking Foundation. The creation and management of VRF instances on the PON interface router are not configured manually but are orchestrated by an SDN Controller (like ONOS) via the VOLTHA software layer. An application running on top of the controller allows an operator to provision a new tenant, which automatically configures the corresponding VRF on the router, the necessary VLAN tags in the OLT, and authenticates the ONU. This makes the patent's concept an obvious implementation detail within a larger, well-documented open-source SDN framework for broadband access.

  3. Combination with Prometheus and YANG/NETCONF: The PON interface router and the OLT expose their per-VRF statistics and configurations via a standardized YANG data model. A NETCONF server on the devices allows for programmatic configuration. An open-source Prometheus "exporter" is used to scrape per-VRF traffic counters (bytes, packets, errors) in real-time. This data is stored in the Prometheus time-series database and visualized in Grafana dashboards, providing per-tenant network visibility. This combination makes the concept of separating traffic obvious for the purpose of per-tenant monitoring and SLA management using widely adopted open-source and standards-based operational tools.

Generated 5/14/2026, 12:49:02 AM

Keep exploring

Other patents in High-Tech (T)

See all High-Tech (T) patents →

This patent in court (2)

2 tracked lawsuits name US 11589142.